Other · Local MCP server
Secret Scanner
Scans files for leaked secrets and API keys.
What the MCP Registry states
The entry as published to the official MCP Registry (read 2026-10-04), latest version.
- Registry name
io.github.4hmetuyar/secret-scanner- Version
- 0.2.10
- Status
- Active
- Category
- other
- Transport
- stdio (local process)
- Package
- npm
- Published
- 2026-10-02
- Updated
- 2026-10-02
- Publisher
- 4hmetuyar (GitHub) · 26 servers with pages here
- Repository
- github.com/GuardBee/guardbee-mcp (folder packages/secret-scanner)
- Source
- Registry API entry
Packages
| Registry | Package | Version | Transport |
|---|---|---|---|
| npm | @guardbee/mcp-secret-scanner | 0.2.10 | stdio |
How to connect Secret Scanner
Secret Scanner runs locally from a Node.js package published to the npm registry: @guardbee/mcp-secret-scanner version 0.2.10. It speaks MCP over stdio, so the client starts it as a program and talks to it through standard input and output. It needs Node.js; clients usually start it with npx — the usual command is npx -y @guardbee/mcp-secret-scanner@0.2.10.
In the mcpServers JSON format that many desktop and editor MCP clients read, the entry looks like this (placeholders in angle brackets):
{
"mcpServers": {
"secret-scanner": {
"command": "npx",
"args": [
"-y",
"@guardbee/mcp-secret-scanner@0.2.10"
]
}
}
}Derived from the registry entry, not tested here. What the server does, and on what terms, is set by its publisher; check its repository or website before giving it access to your accounts or files. How to add an MCP server to an assistant · Before you connect
More from 4hmetuyar (GitHub)
| Server | Runs |
|---|---|
| Memory Poisoning ScannerScans agent code for untrusted input poisoning persistent cross-session memory. | Local · stdio |
| Model ScannerScans ML model files (PyTorch, safetensors, Keras, ONNX) for supply-chain risks. | Local · stdio |
| Oauth AuditorScans MCP server auth code for OAuth 2.1 anti-patterns: token passthrough, missing audience. | Local · stdio |
| Prompt Injection ScannerScans RAG content/scraped pages for indirect prompt injection. | Local · stdio |
| Prompt Leak ScannerCatches leaked credentials and PII in outbound LLM prompts. | Local · stdio |
| Rug Pull DetectorBaselines an MCP server's tools and detects tool-definition changes after approval. | Local · stdio |
| Security ProxyMCP gateway: many servers, one policy, lethal-trifecta blocking, PII masking, audit log. | Local · stdio |
| Security SuiteBundle of secret-scanner, dependency-auditor, ssl-inspector, and dns-intelligence. | Local · stdio |
| Slopsquat ScannerChecks declared npm/PyPI dependencies against real registries to catch slopsquatting. | Local · stdio |
| Tool Poisoning ScannerScans MCP tool definitions for hidden instructions and confused-deputy sinks. | Local · stdio |
| Toxic Flow AuditorFinds lethal-trifecta toxic flows in MCP tool catalogs: untrusted input, sensitive data, egress. | Local · stdio |
| Unbounded Consumption AuditorScans LLM/agent code for Unbounded Consumption / denial-of-wallet risks (OWASP LLM Top 10 2026 #6) | Local · stdio |
More other servers
| Server | Runs |
|---|---|
| SecondBrainNotas diarias, recaps, documentos, tareas, un Atlas de entidades y artefactos de Claude/ChatGPT. | Remote · HTTP |
| Secret Hygiene MCPCount secret-like patterns in bounded local files without returning values, keys, paths,... | Local · stdio |
| Secret Safe EnvWrite secrets into.env without the agent ever seeing the value - Windows masked dialog (繁中 UI) | Local · stdio |
| Secret ScanCheck text for leaked credentials before an agent writes or commits it. Runs locally. | Local · stdio |
| Secret ScannerScan configs, files, or text for leaked secrets and obvious misconfigurations. Nothing stored. | Remote · HTTP |
| SecretcarouselAgent-first secrets vault. Store, rotate, and share credentials from chat. 20 tools. | Remote & Local · SSE, stdio |
| Secrets-LEDetect hardcoded secrets in source and config. Reports masked previews, never the values. | Local · stdio |
| Sector PulseLive US sector rotation: 30 sector baskets ranked every session, versioned rosters, daily record. | Remote · HTTP |